CVE Tools

Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover

SecurityWeekBy Ionut Arghire

PatchThe Events Calendar pluginWordPress

Our summary

StellarWP has patched two unauthenticated remote code execution flaws in The Events Calendar plugin for WordPress: CVE-2026-78159 and CVE-2026-78006, both rated CVSS 9.8. The bugs can allow code or PHP object injection and could result in a complete WordPress site takeover when event comments are enabled. Administrators should update to The Events Calendar 6.17.4.1, as versions before 6.17.3.1 are exposed to both issues and CVE-2026-78006 is fixed in 6.17.4.1.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store